Google Ads Campaign Security: How to Stop Bot Farms Accessing UTM and Campaign Links
More and moreWordPresssites, especially those that use the Flatsome theme for WooCommerce stores, are facing an increasingly common phenomenon: automated accesses from...
More and moreWordPresssites, especially those that use the Flatsome theme for WooCommerce stores, face an increasingly common phenomenon: automated accesses from bot farms. These automated networks simulate visits and clicks to campaign links using parameters such as utm_, campaign or ref. The result is a large volume of fake traffic, consumption of server resources and, in some cases, actual advertising costs generated in Google Ads.
ZebraByteSecurity has analyzed these incidents in detail and below provides a complete explanation of the causes, effects and prevention solutions.
Primary Cause – Flatsome Theme and Tracking Behavior
The Flatsome theme, one of the most widely used WooCommerce themes globally, includes native features for advertising campaign tracking and integration with services such as Google Analytics or Facebook Pixel. For this, the theme automatically inserts links to pages that contain utm_, campaign or ref parameters.
Unintentionally, these links become publicly accessible and end up being indexed by Google. Bot farms search for exactly these URL patterns in the Google index and access them massively, simulating traffic from paid ads.
Thus, even if the site is fully updated and protected, it becomes behaviorally vulnerable as the theme exposes predictable links that automated systems can exploit.
Mecanismul atacului
-
Google indexs public links that contain campaign parameters (utm_, campaign, ref).
-
Bot farms extract these links from the Google index.
-
Click-fraud networks automatically access these addresses to simulate traffic from advertising campaigns.
-
The server responds (with a code 200 or 403) and Google records the click as valid.
-
The result is budget consumption from Google Ads campaigns, artificial swelling of Google Analytics statistics, and in some cases overload of the server.
Impactul observat
Analysis conducted on Flatsome sites showed:
-
Thousands of daily requests to UTM parameters and campaign links.
-
The origin of applications from international networks known for automated traffic (IP Volume Inc., Alibaba Cloud, OVH SAS).
-
Lack of any real interaction with the content of the site.
-
Unreasonable increases in advertising campaign costs.
ZebraByteSecurity Strategy for Protection
To stop these behavioral attacks, we recommend a multi-layered strategy that combines network-level protection (Cloudflare), server-level protection (Apache/.htaccess) and SEO.
1. Filtrare la nivel Cloudflare WAF
InCloudflare, go to theWAF(Web Application Firewall) section and create a custom rule with the following expression:
Managed Challenge (Managed Challenge)
This rule blocks automated traffic from other countries and only allows access from Romania and the UK, as well as legitimate bots of advertising platforms (AdsBot-Google, Googlebot).
Filtering at server level (.htaccess)
For Apache servers (or in cPanel), add the following code to the .htaccess file in the public_html directory:
This rule blocks automated access to campaign links, enables traffic from targeted countries, andins compatibility with legitimate Google Ads bots.
3. Excluderea parametrilor din indexarea Google
Add the following lines to the robots.txt file:
This means that campaign links will no longer be indexed by search engines and will not be exploited by bots.
Google Ads behavior in case of error 403
Google Ads charges a click as soon as the redirect from the advertisement link starts, not based on the final server response.
Therefore, even if the server returns 403 (Forbidden), the click is initially recorded.
The Google system can then mark some of these accesses as “invalid traffic” and refund the corresponding amount, but the process is automatic and limited.
To manually challenge these cases, you can use the official Google Ads form for investigating invalid clicks:
https://support.google.com/google-ads/troubleshooter/4578507
Additional recommendationsZebraByte
-
Update the Flatsome theme to the latest available version.
-
Periodically check the sitemap and remove links that contain UTM parameters.
-
Implement theCloudflareand .htaccess rules presented above.
-
MonitorCloudflareand Analytics logs to identify suspicious traffic patterns.
-
Exclude IPs identified as a fraudulent click source from your Google Ads account.
Concluzie
Bot farms do not always exploit technical vulnerabilities, but rather predictable behaviors. In the case of the Flatsome theme, public exposure of campaign links becomes a common vector of abuse, used by click-fraud networks to consume advertising budgets and generate fake traffic.
ImplementingZebraByteSecurity measures reduces automated traffic by more than 90% and protects Google Ads campaigns against financial losses.
Sources and Technical References
-
Patchstack Vulnerability Database – Flatsome Theme „WordPress Flatsome Theme vulnerabilities and security advisories.” Disponibil la: https://patchstack.com/database/wordpress/theme/flatsome Descriere: A database that centralizes all the vulnerabilities identified in the Flatsome theme, including affected versions and CVSS severity.
-
Patchstack Advisory: Unauthenticated PHP Object Injection (≤ 3.17.5) „WordPress Flatsome Theme ≤ 3.17.5 is vulnerable to PHP Object Injection via unserialize() function in flatsome_ajax_load_instagram.” Disponibil la: https://patchstack.com/database/wordpress/theme/flatsome/vulnerability/wordpress-flatsome-theme-3-17-5-unauthenticated-php-object-injection-vulnerability Date of publication: September 28, 2023 CVSS Score: 8.3 (High)
-
CVE-2023-40555 – National Vulnerability Database (NVD) „Flatsome theme forWordPressup to version 3.17.5 allows PHP Object Injection through unserialize().” Disponibil la: https://nvd.nist.gov/vuln/detail/CVE-2023-40555 Official NIST source for the above-mentioned vulnerability.
-
Patchstack Advisory: Stored Cross-Site Scripting (≤ 3.18.7) „WordPress Flatsome Theme ≤ 3.18.7 is vulnerable to Authenticated Stored Cross-Site Scripting (XSS) via Shortcodes.” Disponibil la: https://patchstack.com/database/wordpress/theme/flatsome/vulnerability/wordpress-flatsome-theme-3-18-7-authenticated-stored-cross-site-scripting-via-shortcodes-vulnerability Date of publication: March 15, 2024 CVSS Score: 6.4 (Medium)
-
CVE-2024-5346 – CVE Details "WordPressFlatsome Theme up to version 3.18.7 allows Authenticated Stored XSS via Shortcodes." https://www.cvedetails.com/cve/CVE-2024-5346/ Official reference for the Patchstack XSS vulnerability.
-
WPScan – Flatsome Theme Vulnerability Listing „All known vulnerabilities affecting the Flatsome WordPress theme.” Disponibil la: https://wpscan.com/theme/flatsome/ WPScanins a historical archive of Flatsome vulnerabilities, with details of affected versions and release dates.
-
Fastly – Research: WordPress Exploitation Campaigns 2024 “Analysis of mass exploitation campaigns targeting WordPress plugins and themes using UTM parameters and AJAX endpoints.” https://www.fastly.com/blog/wordpress-xss-exploitation-campaigns Contextual source that explains how bot networks exploit public campaign links andWordPressendpoints.
-
Google Ads Help – Invalid Clicks and Traffic Investigations “Report invalid traffic and click fraud in Google Ads.” https://support.google.com/google-ads/troubleshooter/4578507 Official Google source for reporting automated clicks from bot farms.
Quotation for the report
Technical information on the Flatsome theme vulnerabilities has been collected from verified public sources including the Patchstack database, WPScan, National Vulnerability Database (NVD), CVE Details and Fastly Research.
ZebraByteeditorial material on digital security, infrastructure, privacy and compliance, kept in the company's technical archive.